Claude Safe Auto Accept
Stop clicking Allow. Keep Claude Code moving — safely.
Claude Safe Auto Accept automatically approves routine Claude Code
tool permission prompts so Claude can keep working without constant
interruptions — except for questions Claude asks you
(AskUserQuestion) and plan reviews (ExitPlanMode), which always still
prompt normally. A built-in safety net also keeps a short list of risky
commands (force-push, hard reset, recursive deletes, credential-file edits)
prompting even in auto-accept mode.
Unlike unrestricted permission bypassing, this extension is designed to
preserve those safety protections rather than blindly approving everything.
Why "Safe" Auto Accept?
The goal is to remove repetitive approval prompts without removing the
protections that actually matter. Today that means:
- ✅ Routine tool permissions are automatically approved.
- ✅ Dangerous shell commands remain protected (
git push --force,
git reset --hard, git branch -D, rm -rf, PowerShell recursive/force
delete).
- ✅ Destructive Git operations remain protected (covered by the same
risky-pattern list above).
- ✅ Credential-sensitive file edits remain protected (
.env, *.pem,
id_rsa, credentials.json, secrets.json, etc.).
- ✅ User questions (
AskUserQuestion) still require your input.
- ✅ Plan reviews (
ExitPlanMode) still require your involvement.
All of the above is enforced by the risky-pattern list and hard-coded
ask-tools described under How it works and
Settings below — nothing here is aspirational marketing, it's
what the shipped hook actually does. That list is configurable and,
being regex-based, isn't foolproof — see
Known limitations. Adds safety guardrails; does not
guarantee that every automatically approved operation is safe.
⚠️ Read this before enabling
Claude Safe Auto Accept removes most of Claude Code's confirmation prompts,
including for running shell commands and editing or deleting files. Per
Anthropic's own documentation, bypassing permission prompts provides "no
protection against prompt injection or unintended actions." Only enable
this in projects and environments you trust, and keep the built-in risky-
pattern safety net turned on unless you have a specific reason to disable it.
Free quota & paid top-ups
The first 200 lifetime auto-approved tool calls are free. Questions,
plan reviews, and anything caught by the risky-pattern safety net are
unlimited and never count against the quota — only genuine auto-accepts
do.
Once the quota (free + purchased) runs out, Claude Safe Auto Accept does
not stop working or start denying anything — it simply falls back to
Claude Code's normal interactive prompting for every tool call, exactly as
if it were disabled, until you add more.
$9.99 buys 7,000 more approvals via Lemon Squeezy:
Claude Safe Auto Accept: Buy More Approvals opens the checkout page.
- After purchase you'll get a license key by email — redeem it with
Claude Safe Auto Accept: Redeem License Key.
- The status bar shows remaining quota (
142/200 free, or total remaining
once you've purchased credits), and switches to a warning style once
you're out.
Local counters, backed by a lightweight server-side check. Both the
free-quota counter and the purchased-credit balance live in local files
(~/.claude-auto-accept/stats.json, license.json) — that stays the
day-to-day source of truth, and hook.ts (the script Claude Code actually
invokes) never touches the network, before or after this. Periodically —
and right after redeeming a license key — the extension reports your
current counts, keyed by VS Code's own machineId
(vscode.env.machineId, a random per-install id VS Code itself generates,
not a hardware identifier), to a small optional Cloudflare Worker + D1
backend, which remembers the highest value it's ever seen for that id. If
your local files are ever missing or show a lower count than the server
remembers, the extension repairs them back up instead of starting fresh.
This raises the bar against resetting your usage by deleting local
files — it's not a guarantee. It doesn't defend against reinstalling VS
Code (which gets a fresh machineId) or against modifying the extension's
own code, which ships as ordinary, readable JavaScript like any VS Code
extension. Only machineId and the two numeric counters are ever sent —
never file contents or command text. See CLOUDFLARE.md
for the full picture, including exactly what's sent and how it's hosted.
How it works
Claude Code (both the CLI and its official VS Code extension) supports a
PreToolUse hook: an external script registered in .claude/settings.json
that Claude Code runs before every tool call, and that returns an
allow / ask / deny decision. This extension:
- Ships a small, dependency-free Node.js hook script.
- When you enable it, registers that script as a
PreToolUse hook in your
global ~/.claude/settings.json — applies to all your projects,
alongside any hooks you already have (nothing else is touched).
- The hook auto-allows every tool call, except:
AskUserQuestion and ExitPlanMode always fall through to the normal
interactive prompt.
- Anything matching a risky pattern (see below) falls through to
ask.
- Every decision is logged to
~/.claude-auto-accept/decisions.log and
streamed live into the "Claude Safe Auto Accept" Output Channel.
There is no way for a VS Code extension to click buttons inside another
extension's UI — this hook mechanism is the only supported integration
point, which is why enabling/disabling writes real Claude Code configuration
rather than trying to watch the screen.
Usage
- Click the "Safe Auto Accept" status bar item (bottom right) to
toggle it on/off. It also shows a running count of how many tool calls
have been auto-accepted (hover for the full allow/ask/deny breakdown).
Or use the Command Palette:
Claude Safe Auto Accept: Enable
Claude Safe Auto Accept: Disable
Claude Safe Auto Accept: Toggle
Claude Safe Auto Accept: Show Log
Claude Safe Auto Accept: Buy More Approvals
Claude Safe Auto Accept: Redeem License Key
Settings
| Setting |
Description |
claudeAutoAccept.riskyPatterns |
Array of rules; each matches a tool + field (e.g. Bash command, or Edit/Write file_path) against a regex and forces ask or deny instead of auto-allow. Ships with defaults for git push --force, git reset --hard, git branch -D, recursive/force deletes, and credential-shaped file paths (.env, *.pem, id_rsa, etc.). |
claudeAutoAccept.additionalAskTools |
Extra tool names that should always fall through to interactive prompting, beyond AskUserQuestion and ExitPlanMode (which are always ask, regardless of this setting). |
Changes to these settings are written to ~/.claude-auto-accept/config.json
and picked up on the hook's next invocation.
Known limitations
- Command matching is regex/substring-based, not a real shell parser — it
can be evaded by sufficiently obfuscated commands. Defaults are written to
favor false positives (an extra prompt) over false negatives.
- v1 only manages the global
~/.claude/settings.json scope (applies to
every project), not per-project .claude/settings.json.
- Requires
node to be available on your PATH (the hook script runs as a
plain Node process spawned by Claude Code).
- Free-quota and purchased-credit tracking gets a server-side backstop keyed
by VS Code's
machineId (see Free quota & paid top-ups
and CLOUDFLARE.md), but that id changes on a fresh VS
Code install/profile, and the check can be bypassed by modifying the
extension's own code. It raises the bar against casual resets; it isn't a
hard guarantee.
License
MIT — see LICENSE.